CVE-2026-57583 | OpenZeppelin Contracts Wizard prior 0.10.11/3.0.1/0.6.2/0.3.1 Comment Generation setInfo securityContact/license code injection
A vulnerability categorized as problematic has been discovered in OpenZeppelin Contracts Wizard. This affects the function setInfo of the component Comment Generation. Executing a manipulation of the argument securityContact/license can lead to code injection.
This vulnerability is tracked as CVE-2026-57583. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More